Description
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
Published: 2026-09-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

IBM Verify Identity Access Advanced Access Control may allow an information disclosure attack. The CVE description indicates that a flaw could enable an unauthorized user to read data that should be confidential. Because the issue is classified as CWE‑1336, it suggests an authority bypass; however, the exact extent of the data exposed is not specified. Based on the description, it is inferred that an attacker possessing sufficient access could exploit the weakness to gain visibility into protected information.

Affected Systems

Affected products include IBM Verify Identity Access and IBM Security Verify Access, as well as their container counterparts. For the non‑container versions, IBM Verify Identity Access v11.0.3 interim fix and earlier baseline versions (v11.0.0) are affected; IBM Security Verify Access v10.0.9.2 interim fix and earlier baseline versions (v10.0.0) are also impacted. Containers are affected for the corresponding 10.0.9.2 and 11.0.3 interim fixes and their baseline 10.0.0 and 11.0.0 images.

Risk and Exploitability

The CVSS score of 7.5 and EPSS score of < 1% indicate a moderate likelihood of exploitation but limited public exploitation data. The vulnerability is not listed in CISA’s KEV catalog and no known exploits are cited. Consequently, the likelihood of active exploitation is uncertain, but the confidentiality impact warrants precaution. Because the flaw is linked to improper authorization logic, any user with elevated privileges could potentially read disallowed data if the vulnerability is exploited.

Generated by OpenCVE AI on September 10, 2026 at 03:52 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Download and apply IBM Verify Identity Access v11.0.3 IF2 via IBM Fix Central.
  • Download and apply IBM Security Verify Access v10.0.9.2 IF2 via IBM Fix Central.
  • For containerized deployments, apply the interim fixes by following the container documentation link provided by IBM.
  • If immediate patching is not feasible, restrict network access to the application endpoints and monitor for anomalous read attempts.

Generated by OpenCVE AI on September 10, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 04 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-1336
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-08T17:34:46.039Z

Reserved: 2026-06-24T22:14:17.818Z

Link: CVE-2026-13297

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T17:16:51.573

Modified: 2026-09-08T18:17:35.057

Link: CVE-2026-13297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:00:06Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine